Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,468 advisories

Loading
AsyncHttpClient re-sends client-wide realm credentials to a cross-origin redirect target Moderate
CVE-2026-85717 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
AsyncHttpClient sends origin credentials to the proxy on the plaintext CONNECT request Moderate
CVE-2026-85720 was published for org.asynchttpclient:async-http-client (Maven) Sep 17, 2026
hyperxpro Credited to hyperxpro
rclone: http backend forwards custom/auth headers to a different host on redirect Low
CVE-2026-88013 was published for github.com/rclone/rclone (Go) Sep 10, 2026
iaohkut Credited to iaohkut and ncw ncw ncw
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High
CVE-2026-59158 was published for nuxt-ollama (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
ProTip! Advisories are also available from the GraphQL API